4 ms·
The file has been created in such a way that the web browser is ignoring the non-html parts of the document, while the image renderer is ignoring the parts that
by aidanns 14y ago
The file has been created in such a way that the web browser is ignoring the non-html parts of the document, while the image renderer is ignoring the parts that make up the html page.
The first part probably isn't too hard, since most web browsers go to great lengths to render non-standard html in a sensible way, I'm not too sure about the second part. I'm guessing the jpeg spec has some variable length space in some kind of file header that the html for the page can be put in to.
I read something similar a while back (I think it was called a Jafar attack) where a clever person worked out how to create a file that was both a valid .gif image and .jar java executable.
- tedunangst 14y agojar files are just zip files, which put the header info at the end of the file, making it very easy to construct a jar/zip that's also got a different file header at the front. bad news for web apps which allow such files to be uploaded without inspecting them. it's not a terrible idea to always transcode all uploaded images/videos to prevent that.
- duskwuff 14y ago> I think it was called a Jafar attack GIFAR: http://en.wikipedia.org/wiki/GIFAR http://en.wikipedia.org/wiki/GIFAR